This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
The remote web server hosts a web application that is affected by a
cross-site scripting vulnerability.
The remote server hosts an install of Atlassian Confluence that is
affected by a cross-site scripting vulnerability related to the
'ConfluenceVelocityServlet.class' and error pages.
User-supplied input in a URL is not validated properly before being
returned in an error page. This can result in an attacker-controlled
script running in the user's browser.
See also :
Apply the vendor patches or update to Confluence version 4.1.9 or later.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true
Family: CGI abuses : XSS
Nessus Plugin ID: 62356 ()
Bugtraq ID: 55509